User guide

EDA System Design
98
1/1551-HSC 901 35/3 Uen C 2005-12-02
The use of PPP creates a kind of tunnel between the CPE and the BRAS.
This provides an inherent level of security, because it creates layer-2
separation of the subscribers. Configuring the IP DSLAM filter to allow only
PPPoE frames provides additional security.
The security level can be extended with the use of VLAN to separate traffic
types within the Access Domain.
Multiple providers may each have a BRAS located within a single Access
Domain. These BRAS servers may be separated in different VLANS,
causing each subscriber to be able to reach only one BRAS, or the BRAS
may be located within the same broadcast domain. In the latter scenario, a
subscriber can access any of the BRAS servers, but must of course still
perform a successful login in order to be authenticated by the BRAS.
It is possible to provide practically any IP service via the BRAS; however,
IP multicast services to PPP-connected subscribers requires that the traffic
is sent as unicast from the BRAS to each of these subscribers.
The Telephony over IP (ToIP) service offered by the Voice Gateway may
also be accessed via the BRAS, thus requiring the ToIP client to perform a
PPP-based authentication before being authorized to use this service.
However, the use of PPP as encapsulation protocol for voice may not be
optimal in terms of delay, Calculation of the extra delay, using a specific
BRAS must be made before choosing this possibility.
An example of an EDA solution using a BRAS, and employing both data
access services and Telephony over IP, is depicted in Figure 61 on page
99. The BRAS offers connectivity towards remote service nodes (ISP PoP)
through tunneling of PPP sessions over a backbone network. The BRAS,
acting as an ISP PoP, may also terminate the PPP sessions. For this
purpose a RADIUS Server may optionally be located within the Access
Domain (not shown in Figure 61 on page 99).
The Voice Gateway provides Telephony over IP function towards the
PSTN. If the telephone calls are encapsulated using PPP sessions, they
must be terminated in the BRAS before they are passed on to the Voice
Gateway. In that case it may be more optimal (with respect to delay), to
send the traffic directly from the BRAS to the Voice Gateway instead of via
the upper aggregation switch.